7.8
CVE-2024-23138
- EPSS 0.07%
- Veröffentlicht 18.03.2024 00:15:07
- Zuletzt bearbeitet 31.12.2025 00:41:24
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Advance Steel Version >= 2021 < 2021.1.4
Autodesk ≫ Advance Steel Version >= 2022 < 2022.1.4
Autodesk ≫ Advance Steel Version >= 2023 < 2023.1.5
Autodesk ≫ Advance Steel Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Architecture Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Architecture Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Architecture Version >= 2023 <= 2023.1.5
Autodesk ≫ Autocad Architecture Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Electrical Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Electrical Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Electrical Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Electrical Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Lt SwPlatform- Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Lt SwPlatform- Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Lt SwPlatformmacos Version >= 2022 < 2022.4.1
Autodesk ≫ Autocad Lt SwPlatform- Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Lt SwPlatformmacos Version >= 2023 < 2023.3.1
Autodesk ≫ Autocad Lt SwPlatformmacos Version >= 2024 < 2024.1.2
Autodesk ≫ Autocad Lt SwPlatform- Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Map 3d Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Map 3d Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Map 3d Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Map 3d Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Mechanical Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Mechanical Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Mechanical Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Mechanical Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Mep Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Mep Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Mep Version >= 2023 < 2023.15
Autodesk ≫ Autocad Mep Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Plant 3d Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Plant 3d Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Plant 3d Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Plant 3d Version >= 2024 < 2024.1.3
Autodesk ≫ Dwg Trueview Version >= 2022 < 2022.1.4
Autodesk ≫ Dwg Trueview Version >= 2023 < 2023.1.5
Autodesk ≫ Dwg Trueview Version >= 2024 < 2024.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.213 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@autodesk.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.